ser Researchers Find Serious Flaws In WordPress Plugins Used On 400k Sites By packetstormsecurity.com Published On :: Fri, 17 Jan 2020 16:27:25 GMT Full Article headline flaw wordpress
ser Amazon Granted Patent For Surveillance Drones Service By packetstormsecurity.com Published On :: Mon, 24 Jun 2019 16:43:41 GMT Full Article headline government privacy usa amazon spyware
ser AWS S3 Server Leaks Data From Fortune 100 Companies: Ford, Netflix, TD Bank By packetstormsecurity.com Published On :: Fri, 28 Jun 2019 15:12:03 GMT Full Article headline privacy amazon data loss
ser Alexa, Siri, Google Smart Speakers Hacked Via Laser Beam By packetstormsecurity.com Published On :: Tue, 05 Nov 2019 15:11:49 GMT Full Article headline hacker amazon flaw google apple
ser SETI Has Observed A Strong Signal From A Sun-Like Star By packetstormsecurity.com Published On :: Mon, 29 Aug 2016 13:45:41 GMT Full Article headline space science
ser NASA Fears Internal Server Hacked, Staff Personal Info Swiped By packetstormsecurity.com Published On :: Wed, 19 Dec 2018 04:01:47 GMT Full Article headline government privacy usa space data loss science nasa
ser Dassault Systèmes Introduces SOLIDWORKS 2020, Designed for the 3DEXPERIENCE.WORKS Portfolio, Accelerating the Product Development Process for Millions of Users By www.3ds.com Published On :: Tue, 17 Sep 2019 15:03:38 +0200 •Customers can seamlessly extend their design to manufacturing ecosystem to the cloud with the integrated 3DEXPERIENCE.WORKS portfolio, enabling new levels of functionality, collaboration, agility and operational efficiency •Latest release of 3D design and engineering portfolio features hundreds of enhancements, new capabilities and workflows to accelerate and improve product development •Over six million SOLIDWORKS users can innovate products faster with better performance and streamlined... Full Article 3DEXPERIENCE SOLIDWORKS Corporate Products
ser VirtualTablet Server 3.0.2 Denial Of Service By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 17:22:22 GMT VirtualTablet Server version 3.0.2 denial of service proof of concept exploit. Full Article
ser OpenSSL signature_algorithms_cert Denial Of Service By packetstormsecurity.com Published On :: Fri, 01 May 2020 19:22:22 GMT Proof of concept denial of service exploit for the recent OpenSSL signature_algorithms_cert vulnerability. Full Article
ser Upgrade of Managed DSLS Service on Feb, 29th 3:00AM (UTC+1). Estimated duration: 3 hours By www.3ds.com Published On :: Tue, 25 Feb 2020 17:29:19 +0100 Managed DSLS Service will be upgraded on Feb, 29th (starting Saturday Feb, 29th 2020 - 3AM - UTC+1) Full Article 3DEXPERIENCE Managed DSLS maintenance
ser (On-Premises Only) Security advisory for Simulation Process Intelligence (3DOrchestrate Services) on 3DEXPERIENCE: March 11th, 2020 By www.3ds.com Published On :: Tue, 10 Mar 2020 11:04:49 +0100 A vulnerability associated with Use of Hard-coded Credentials (CWE-798) exists in Simulation Process Intelligence (3DOrchestrate Services) on premises licensed program. The security risk is evaluated as High (CVSS v.3.0 Base Score 8.0) and affects all 3DEXPERIENCE releases (from 3DEXPERIENCE R2014x to 3DEXPERIENCE R2020x). Full Article 3DEXPERIENCE 3DEXPERIENCE 3DEXPERIENCE R2014x 3DEXPERIENCE R2015x 3DEXPERIENCE R2016x 3DEXPERIENCE R2017x 3DEXPERIENCE R2018x 3DEXPERIENCE R2019x
ser Bluetooth Exploit Can Track And Identify Mobile Device Users By packetstormsecurity.com Published On :: Wed, 17 Jul 2019 13:08:25 GMT Full Article headline privacy wireless spyware
ser VoIP System Users Can Be Targeted In Attacks By packetstormsecurity.com Published On :: Fri, 26 Sep 2008 08:10:30 GMT Full Article voip
ser Hacker Admits Stealing, Reselling VoIP Services By packetstormsecurity.com Published On :: Thu, 04 Feb 2010 14:15:02 GMT Full Article hacker voip
ser Skype Flaw Allows For Collection Of User IP Addresses By packetstormsecurity.com Published On :: Tue, 01 May 2012 21:23:32 GMT Full Article headline privacy flaw voip skype
ser Salt Bugs Allow Full RCE As Root On Cloud Servers By packetstormsecurity.com Published On :: Fri, 01 May 2020 13:36:48 GMT Full Article headline flaw
ser Deep Instinct Windows Agent 1.2.29.0 Unquoted Service Path By packetstormsecurity.com Published On :: Fri, 06 Mar 2020 15:02:22 GMT Deep Instinct Windows Agent version 1.2.29.0 suffers from an unquoted service path vulnerability. Full Article
ser Microsoft Windows SE_SERVER_SECURITY Security Descriptor Owner Privilege Escalation By packetstormsecurity.com Published On :: Wed, 15 Apr 2020 18:44:19 GMT In Microsoft Windows, by using the poorly documented SE_SERVER_SECURITY Control flag it is possible to set an owner different to the caller, bypassing security checks. Full Article
ser Microsoft Windows Unquoted Service Path Privilege Escalation By packetstormsecurity.com Published On :: Thu, 16 Apr 2020 20:01:59 GMT This Metasploit module exploits a logic flaw due to how the lpApplicationName parameter is handled. When the lpApplicationName contains a space, the file name is ambiguous. Take this file path as example: C:program fileshello.exe; The Windows API will try to interpret this as two possible paths: C:program.exe, and C:program fileshello.exe, and then execute all of them. To some software developers, this is an unexpected behavior, which becomes a security problem if an attacker is able to place a malicious executable in one of these unexpected paths, sometimes escalate privileges if run as SYSTEM. Some software such as OpenVPN 2.1.1, OpenSSH Server 5, and others have the same problem. Full Article
ser Microsoft In More Hacking Misery By packetstormsecurity.com Published On :: Tue, 21 Jan 2014 16:24:20 GMT Full Article headline hacker microsoft flaw syria
ser Numara / BMC Track-It! FileStorageService Arbitrary File Upload By packetstormsecurity.com Published On :: Tue, 21 Oct 2014 02:43:59 GMT This Metasploit module exploits an arbitrary file upload vulnerability in Numara / BMC Track-It! v8 to v11.X. The application exposes the FileStorageService .NET remoting service on port 9010 (9004 for version 8) which accepts unauthenticated uploads. This can be abused by a malicious user to upload a ASP or ASPX file to the web root leading to arbitrary code execution as NETWORK SERVICE or SYSTEM. This Metasploit module has been tested successfully on versions 11.3.0.355, 10.0.51.135, 10.0.50.107, 10.0.0.143, 9.0.30.248 and 8.0.2.51. Full Article
ser Grum Botnet Loses Dutch Servers By packetstormsecurity.com Published On :: Wed, 18 Jul 2012 15:28:08 GMT Full Article headline cybercrime botnet netherlands
ser Microsoft Warns Of Hacking Group Targeting Vulnerable Web Servers By packetstormsecurity.com Published On :: Fri, 13 Dec 2019 15:07:06 GMT Full Article headline hacker microsoft
ser Over 350,000 Microsoft Exchange Servers Still Open To Flaw By packetstormsecurity.com Published On :: Tue, 07 Apr 2020 16:36:12 GMT Full Article headline microsoft flaw patch
ser Chinese APT Now Leveraging Pulse And Fortinet VPN Servers By packetstormsecurity.com Published On :: Thu, 05 Sep 2019 13:39:37 GMT Full Article headline hacker privacy china flaw cyberwar backdoor cryptography
ser Researchers Find Stealthy MSSQL Server Backdoor By packetstormsecurity.com Published On :: Mon, 21 Oct 2019 16:39:18 GMT Full Article headline microsoft china cyberwar backdoor
ser IBM: Heartbleed Attacks Thousands Of Servers Daily By packetstormsecurity.com Published On :: Wed, 27 Aug 2014 15:23:38 GMT Full Article headline hacker ibm flaw cryptography
ser ProficySCADA For iOS 5.0.25920 Denial Of Service By packetstormsecurity.com Published On :: Sun, 22 Mar 2020 14:22:22 GMT ProficySCADA for iOS version 5.0.25920 suffers from a denial of service vulnerability. Full Article
ser File Sharing And Chat 1.0 Denial Of Service By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 14:54:09 GMT File Sharing and Chat version 1.0 for iOS suffers from a denial of service vulnerability. Full Article
ser Transfer Master 3.3 Denial Of Service By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 14:58:27 GMT Transfer Master version 3.3 for iOS suffers from a denial of service vulnerability. Full Article
ser McAfee Anti-Hacking Service Exposed Users To Banking Malware By packetstormsecurity.com Published On :: Thu, 16 Nov 2017 15:05:23 GMT Full Article headline malware bank cybercrime fraud flaw identity theft mcafee
ser XSSer Penetration Testing Tool 1.8-1 By packetstormsecurity.com Published On :: Mon, 23 Sep 2019 20:04:03 GMT XSSer is an open source penetration testing tool that automates the process of detecting and exploiting XSS injections against different applications. It contains several options to try to bypass certain filters, and various special techniques of code injection. Full Article
ser XSSer Penetration Testing Tool 1.8-2 By packetstormsecurity.com Published On :: Mon, 18 Nov 2019 15:16:36 GMT XSSer is an open source penetration testing tool that automates the process of detecting and exploiting XSS injections against different applications. It contains several options to try to bypass certain filters, and various special techniques of code injection. Full Article
ser RSA BSAFE Crypto Attacks / Denial Of Service By packetstormsecurity.com Published On :: Mon, 17 Aug 2015 16:07:08 GMT RSA BSAFE Micro Edition Suite, Crypto-C Micro Edition, Crypto-J, SSL-J and SSL-C all suffer from various crypto, denial of service, and underflow vulnerabilities. Full Article
ser Apache2 Web Server Hardening Article By packetstormsecurity.com Published On :: Mon, 10 Feb 2020 15:20:36 GMT This is an article discussing Apache2 Web Server hardening. Written in Turkish. Full Article
ser Millions Of Facebook User Phone Numbers Exposed Online, Researchers Say By packetstormsecurity.com Published On :: Thu, 19 Dec 2019 17:23:52 GMT Full Article headline privacy phone data loss flaw facebook social
ser Facebook To Notify Users Of Third-Party App Logins By packetstormsecurity.com Published On :: Wed, 15 Jan 2020 17:03:35 GMT Full Article headline privacy password facebook social
ser Facebook Sues SDK Maker For Secretly Harvesting User Data By packetstormsecurity.com Published On :: Fri, 28 Feb 2020 07:05:36 GMT Full Article headline privacy data loss facebook
ser McDonald's India Delivery App Leaks User Data By packetstormsecurity.com Published On :: Mon, 20 Mar 2017 15:46:49 GMT Full Article headline privacy phone india data loss
ser India's Zomato Says Data From 17 Million Users Stolen By packetstormsecurity.com Published On :: Thu, 18 May 2017 14:15:24 GMT Full Article headline hacker privacy india data loss
ser Data Of Nearly 700,000 Amex India Customers Exposed Via Unsecured MongoDB Server By packetstormsecurity.com Published On :: Wed, 07 Nov 2018 16:32:01 GMT Full Article headline privacy bank india cybercrime data loss fraud
ser Google Now Charges The Government For User Data Requests By packetstormsecurity.com Published On :: Mon, 27 Jan 2020 22:45:22 GMT Full Article headline government privacy usa data loss google spyware
ser Pachev FTP Server 1.0 Path Traversal By packetstormsecurity.com Published On :: Thu, 23 Jan 2020 14:44:44 GMT Pachev FTP Server version 1.0 suffers from a path traversal vulnerability. Full Article
ser Romanian Cops Cuff Suspected Serial Hacker TinKode By packetstormsecurity.com Published On :: Wed, 01 Feb 2012 16:15:08 GMT Full Article headline hacker government usa romania
ser DNS Servers Filled With Wrong Kool-Aid In Romania By packetstormsecurity.com Published On :: Thu, 29 Nov 2012 07:22:09 GMT Full Article headline dns romania
ser Cisco Elastic Services Controller Allows Takeover By packetstormsecurity.com Published On :: Wed, 08 May 2019 13:07:21 GMT Full Article headline flaw patch cisco
ser HC10 HC.Server Service 10.14 Remote Invalid Pointer Write By packetstormsecurity.com Published On :: Mon, 17 Jun 2019 17:03:28 GMT The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS if attackers can reach the service on port 8794. In addition this can potentially be leveraged for post exploit persistence with SYSTEM privileges, if physical access or malware is involved. If a physical attacker or malware can set its own program for the service failure recovery options, it can be used to maintain persistence. Afterwards, it can be triggered by sending a malicious request to DoS the service, which in turn can start the attackers recovery program. The attackers program can then try restarting the affected service to try an stay unnoticed by calling "sc start HCServerService". Services failure flag recovery options for "enabling actions for stops or errors" and can be set in the services "Recovery" properties tab or on the command line. Authentication is not required to reach the vulnerable service, this was tested successfully on Windows 7/10. Full Article
ser Microsoft Windows NtUserSetWindowFNID Win32k User Callback By packetstormsecurity.com Published On :: Tue, 16 Jul 2019 20:32:16 GMT An elevation of privilege vulnerability exists in Microsoft Windows when the Win32k component fails to properly handle objects in memory. This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This Metasploit module is tested against Windows 10 v1703 x86. Full Article
ser Plantronics Hub SpokesUpdateService Privilege Escalation By packetstormsecurity.com Published On :: Wed, 15 Jan 2020 17:07:53 GMT The Plantronics Hub client application for Windows makes use of an automatic update service SpokesUpdateService.exe which automatically executes a file specified in the MajorUpgrade.config configuration file as SYSTEM. The configuration file is writable by all users by default. This module has been tested successfully on Plantronics Hub version 3.13.2 on Windows 7 SP1 (x64). This Metasploit module has been tested successfully on Plantronics Hub version 3.13.2 on Windows 7 SP1 (x64). Full Article
ser Windscribe WindscribeService Named Pipe Privilege Escalation By packetstormsecurity.com Published On :: Wed, 05 Feb 2020 18:54:05 GMT The Windscribe VPN client application for Windows makes use of a Windows service WindscribeService.exe which exposes a named pipe \.pipeWindscribeService allowing execution of programs with elevated privileges. Windscribe versions prior to 1.82 do not validate user-supplied program names, allowing execution of arbitrary commands as SYSTEM. This Metasploit module has been tested successfully on Windscribe versions 1.80 and 1.81 on Windows 7 SP1 (x64). Full Article